SavageVentures
SAM Internal platform · one engine, every Savage brand

Savage Audience Manager.

The engagement platform Savage Ventures' brands run on. Contacts, segments, campaigns, journeys, deals and audience analytics — one app, with a workspace per brand. Every brand works its own audience, sends as itself, and never sees another brand's data.

sam.savage.ventures · a Savage Ventures platform
One app — brands switched in-app, not by URL Each brand sends as itself New brand: a wizard, not an engineer Per-brand costs & budgets Never touches debtors — fail-closed firewall First brand aboard: My Doctor Hank
What SAM does

Run every brand's audience from one place

SAM replaces the stack a brand would otherwise rent — email marketing, CRM, automations, support desk — with one platform Savage already owns. My Doctor Hank alone folds in a ~$4k/month tool stack. Operators get one product to learn; every brand gets the full suite.

Contacts & CRM

Every brand's audience in one place — contacts with custom fields, leads, deals and sales pipelines, scoped to the brand's workspace.

Segments & audiences

Filter contacts into reusable segments ("booked in the last 90 days") with a segment builder; segments feed campaigns and journeys directly.

Campaigns & journeys

One-shot sends or multi-step automations — welcome series, re-engagement — executed over days by the journey runner, across email and SMS.

Templates & content

A brand-scoped template editor with personalization fields. A PII firewall blocks sensitive fields (SSN/DOB-class) from ever entering a template.

Audience analytics

Opens, clicks, conversions, unsubscribes and suppression — recorded per workspace, visible only inside it.

Next · Phase 2

Support inbox

A per-brand support desk — inbound email/SMS threads, queues, SLAs, macros and CSAT — keyed to marketing contacts, never to collections records.

What running a campaign looks like marketer

  1. Sign in to SAM. A My Doctor Hank marketer lands in the MDH workspace — Savage chrome, MDH context accent, MDH contacts. No other brand's data, no collections screens.
  2. Build the audience. Filter contacts into a segment; everything is scoped to the workspace automatically.
  3. Design the message. Pull an MDH template, personalize with allowed fields — the PII firewall handles the rest.
  4. Send or automate. A one-shot blast, or a journey the runner executes over days.
  5. It goes out as the brand. MDH's from-address, MDH's legal footer, MDH's number, MDH's unsubscribe page — resolved automatically from the workspace.
  6. Measure. Opens, clicks and unsubscribes land in the workspace's analytics, and the send's cost lands in the brand's cost rollup.
One app, every brand

Workspaces: switch brands inside the app

SAM is one app at one address — sam.savage.ventures. Each brand is a workspace selected inside the app: a switcher in the header for people who belong to several, a pinned home for people who belong to one. No per-brand URLs to remember, one login, one product.

sam.savage.ventures Savage Audience Manager
Savage platform chrome
My Doctor Hank+ Next brand
My Doctor Hank workspace

The brand's logo, color and voice live here — on its contacts, its campaigns, and everything it sends. The frame around it stays Savage, always.

The platform is always Savage

Nav, shell, login, the SAM wordmark and bolt. An operator switching between brand workspaces stays in the same product — the workspace chip and header tint tell them where they're acting.

The output is always the brand

What the audience sees is fully the brand's: its email from-identity and legal footer, its SMS sender, its unsubscribe and landing pages on its own domain. Brand identity outward is a compliance artifact, not a theme.

Who sees what

Marketers and support agents belong to specific workspaces and see only those. Savage leadership operates across all brands. Membership is the grant — no membership, no rows.

Sending identity

Each brand sends as itself — end to end

Every workspace carries its own verified sending identity, and every send resolves it automatically. A half-configured brand sends nothing — it never falls back to another brand's identity.

IdentityEvery brand carriesMy Doctor Hank, for exampleWhy it matters
Email from-domainIts own verified sending domainMDH's verified domainMail arrives signed as the brand
CAN-SPAM footerIts own legal name + postalMDH legal name + postalThe footer is a legal identity, not a nicety
SMS number + A2P registrationIts own number + carrier registrationMDH's number, registration pendingEach brand's carrier status gates only its own texts
Unsubscribe & landing originIts own domainMDH's own domainOpt-out lands on the brand the reader knows

Fail-closed, on purpose

Identity resolution refuses the send when anything required is missing or unverified — a misconfigured brand can't accidentally send under another brand's identity. SMS stays dark per brand until that brand's carrier registration clears; email-only launch is fine in the meantime.

Self-service Brand CMS

Launch the next brand without an engineer

A new brand is data, not a deploy. A Savage platform-admin opens the Brands console, runs a six-step wizard — identity, sending identity, team — and activates. No code, no migration, no DNS or hosting work per brand; every action is audited. That's what makes each new brand near-free.

Settings → Platform → Brands+ Create Brand
BrandOutward originMembersHealth · Email / SMS / A2PActive
My Doctor Hank mdhmydoctorhank.com3EmailSMSA2P
New Brand draft0EmailSMSA2P

Chips verified pending not set — live vendor-connection health per brand. Deactivate pauses that brand's journeys and campaigns and blocks its members' sign-in. Draft rows (wizard incomplete) are resumable. Figures illustrative.

The Create-Brand wizard — six steps, then live

1Auto

Identity & Theme

Name, slug, logo, favicon, color tokens, login artwork. The brand exists — and is reachable in-app — from this step.

→ the workspace record + brand assets
2Manual

Outward domain · optional

No operator URL to set up — SAM lives at one address. This step only points the brand's outward pages (unsubscribe, landing) at the brand's own domain, with instructions shown and status tracked.

→ the brand's public origin
3AutoManual

Email sending

From-address, from-name, CAN-SPAM legal name + postal. The wizard registers the sending domain, shows the exact DNS records to paste, and polls until verified.

→ per-brand email identity, verified
4AutoLatency

SMS & Voice · skippable

Search and purchase a number, submit the brand's own carrier (A2P 10DLC) registration. Approval takes 1–3 weeks; SMS stays dark until it clears.

→ per-brand number + carrier registration
5Auto

Team

Invite members by email, assign a role (marketer / support agent / admin) and workspace membership. Reuses the platform's existing invite flow.

→ users + workspace memberships
6Auto

Review & Activate

Live checklist of steps 1–5. Activation needs identity + a verified email domain — email-only launch is fine while carrier approval pends.

→ brand live; members sign in and switch to it

Honest about what's automated vs. waited-on

Automated: creating the brand, email-domain registration + verification polling, number purchase, carrier submission, team invites — and because workspaces are selected in-app, a new brand needs zero hosting or DNS work of its own. The only real waits: pasting DNS records at the registrar for the brand's sending domain, and carrier approval (1–3 weeks) — each surfaced as a status chip, never a silent hang. Steady state: a new brand is under an hour of admin work plus those external waits.

Costs & budgets

Know what every brand costs to run

All brands run on Savage's shared vendor accounts, so SAM attributes spend per brand — every email, SMS segment, voice minute, letter and AI token is stamped with its workspace and rolled up nightly. Budgets alert when a brand runs hot; monthly invoices are reconciled so hidden fees surface as visible drift.

SAM run-cost · month to date$1,240
Other brands · $770My Doctor Hank · $470
Non-SAM traffic on the shared vendor accounts is tracked separately and shown only as context — never counted as a brand cost. Figures illustrative.

The ROI line

Each brand's run-cost renders against the legacy stack it replaced — "replaces $4,000/mo → running at ~$650/mo" — so the portfolio sees the consolidation payoff per brand, every month.

My Doctor Hank · this month

ChannelVolumeCostSource
Email82,400 msgs$0.00subscription
SMS41,200 seg$312.40actual
Voice1,180 min$94.40actual
Letters320$224.00actual
AI2.1M tok$18.90rated
Storage12 GB·mo$2.40rated
Replaces a $4,000/mo legacy stack ≈ $652/mo

Budgets & alerts

Per-brand monthly cap with a warning threshold, month-to-date utilization bars, and breach history. Alerts route through the platform's notification matrix, deduped per brand per day.

Rates, reconciliation & export

Editable, effective-dated rates fill in where vendors bill by subscription; each month's real invoices are keyed in and compared against tracked and attributed spend, so drift is visible, never absorbed. CSV export for internal cost allocation.

One account per vendor — by design

A new brand does not need its own vendor logins. It adds its own resources — a verified email domain, a phone number — inside Savage's shared accounts, and cost splits out by the workspace stamp. The one per-brand external step is US SMS: carriers require each brand to register under its own legal identity (a registration, not an account), which the wizard submits and tracks.

Trust & compliance

Two walls, both fail-closed

SAM lives entirely on the marketing side of a hard population firewall — it never touches collections or debtor data — and adds a second wall between brands. Both are enforced in the database and at the send chokepoint — not by convention.

Wall 1 · The audience firewall

Marketing contacts and debtors are separate populations. A marketing send that targets a debtor throws at the chokepoint — SAM structurally cannot reach the collections side, for any brand, ever.

Wall 2 · Brand-to-brand isolation

Default-deny, workspace-scoped row security on every audience table. A brand's marketer sees only their workspace — proven by an automated acceptance test: a brand's query returns zero contacts from any other workspace.

Guardrails on top

Scoped roles keep marketers out of admin surfaces; the PII firewall blocks sensitive fields from templates and vendor payloads; every brand-management action is written to the audit log.

Every send runs the same gauntlet

01
Audience
Contacts matched by segment, scoped to the brand's workspace
02
Firewall check
Marketing-only — throws if any recipient is a debtor
03
Suppression
Unsubscribes and suppressions honored before anything sends
04
Identity resolve
The brand's from-identity, footer, number and opt-out origin — or the send is refused
05
Dispatch & track
Sent, then opens / clicks / unsubscribes recorded to the workspace

What a brand's marketer can — and can never — touch

✓ Inside their workspace
  • Their own contacts, segments & custom fields
  • Their own campaigns, journeys & automations
  • Their own deals & pipeline, templates & analytics
  • Send via their brand's own domain & number
✕ Ever
  • Another brand's contacts, deals or pipeline
  • Any debtor, account or payment record
  • Collections, compliance or admin screens
  • A marketing message to a debtor — hard-throws
How it's built · for the diligence-minded

One codebase, one database, one wall per dimension

One product, one codebase, one database. SAM runs on an engagement engine already proven in production at high volume, with a workspace dimension on top. One app, host-routed at the edge; brands are rows, not deployments.

Front door · one host, routed at the edge
sam.savage.ventures
SAM's single home — its own theme and login. Workspace selection happens in-app; there are no per-brand domains to provision, ever.
ONE codebase, ONE deployEvery brand runs the same app. A new brand changes data, not infrastructure.
Workspaces · logical tenants
My Doctor Hank
workspace = 'mdh'
+ Next Savage brand
created in the Brand CMS — a data row, not a deploy
Shared engine · one Postgres database
Audience data
contacts · campaigns · journeys · segments · deals · templates — workspace-scoped, default-deny RLS
Channel plumbing
email · SMS · voice · letters, plus the journey runner — battle-tested in production
Identity & config
shared auth, per-workspace sending identities, audited admin config

Why one database, not one per brand

Every workspace shares the same channel tables, journey runner, senders, auth and config. A database per brand would mean an auth realm, migration train and config project per brand — infrastructure that scales with brand count instead of with data. Logical isolation — a workspace column plus default-deny row security — is the boundary, and it's enforced by an automated acceptance test.

The option this preserves

SAM is internal-only today: no billing, no self-serve signup, no untrusted tenants. But the discipline — one workspace column everywhere, default-deny policies, fully workspace-resolved sending identities, zero hardcoded brand strings in the shell — is exactly the shape an external SaaS needs. If Savage ever sells it, the lift is smaller by design.

The roadmap

From a sending engine to an audience platform

The multi-brand foundation — workspaces, isolation, identities, the Brand CMS, cost attribution — is built and rolling out on a staged go-live. The support desk ships next. Beyond that, the roadmap turns SAM into the full stack a brand would otherwise rent from Klaviyo, Braze, Segment and Mixpanel — owned, first-party, and run entirely inside SAM. An order of operations, not a schedule.

✓ Built — the foundation

A multi-brand engagement engine

rolling out now, staged go-live
  • Every brand walled off in its own workspace
  • Self-service Brand CMS — a new brand, no engineer
  • Per-brand sending identities, fail-closed
  • Contacts, segments, campaigns, journeys, deals, analytics
  • Per-brand cost attribution, budgets & reconciliation
→ Ahead — the platform

A first-party audience platform

next: the support desk · then the arc below
  • Per-brand support inbox with SLAs & CSAT
  • Know what every audience member actually does
  • Audiences that build themselves from behavior
  • Every message tested — winners chosen automatically
  • An AI copilot that writes, segments and explains

The seven highest-leverage bets

01
The foundation bet

SAM Signals — first-party behavioral events

A lightweight tag on each brand's site turns every view, click and action into a first-party event tied to that contact. It's the one primitive everything else needs — it replaces rented analytics for the brands and turns SAM from a broadcaster into a system that actually knows its audience.

02

Audiences that build themselves

Segments that react to behavior — "opened the last three but never clicked" — plus auto-scored traits (engagement tier, value, recency) that keep every contact current.

03

Built-in experimentation

A/B/n test subject lines, content and send time on any campaign, with the winner picked automatically — reusing a testing engine the platform already owns.

04

Journey orchestration

Journeys that wait for a real action, branch on a goal, and exit on conversion — with portfolio-wide frequency guardrails so no one is ever over-messaged.

05

Deliverability command center

Every brand shares one sending reputation. This watches each brand's inbox health, warms up new domains, and protects the whole portfolio.

06

Campaign Copilot

AI that turns a plain-English request into an audience, drafts and varies the copy, and explains performance — governed and cost-attributed inside SAM.

07

Owned surfaces

On-brand forms, landing pages and a real preference center on each brand's own domain — every lead and opt-in captured first-party, never rented.

One constraint shapes all of it

Every capability lives inside SAM's own admin. No outside dashboard a brand logs into; the delivery vendors stay pure pipes. One platform replaces the half-dozen tools a brand would otherwise stitch together — and every dollar of that spend folds into the engine Savage already owns.

Bottom line

One engine Savage owns, every brand runs on

~$4k/mo
MDH's rented stack, folded into the platform
1 app
one address, one login — brands switched in-app
N brands
each new one via the wizard — no engineer
0 debtors
marketing can never reach collections — fail-closed

Savage Audience Manager is the audience platform for the Savage Ventures portfolio: one product, a workspace per brand, each brand sending as itself with its costs attributed and its audience walled off. It runs on an engagement engine already proven in production — which is why the foundation cost weeks, not quarters — and the roadmap ahead turns it into the first-party platform the portfolio's brands would otherwise rent, piece by piece, from someone else.

Savage Audience Manager
A Savage Ventures platform · building the tools our brands run on
sam.savage.ventures
a Savage Ventures platform